CVE-2026-34968

Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process.


We have discovered 271 live websites that are affected by CVE-2026-34968.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains271 live websites (100% of Adminer install base)
Vulnerable Versions
  • from 0 through 5.4.3
Vulnerable Versions Count16 versions ( 89% of all versions)



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • slpoiuewalspoid-dotcom (reporter)

Website Distribution by Country

Number of websites using CVE-2026-34968
United States43 websites



Czech Republic87 websites
Germany55 websites
France26 websites
Slovakia9 websites
Sweden7 websites
Belgium6 websites
Australia4 websites
China4 websites
Spain4 websites

Website Distribution by TLD

Number of websites using CVE-2026-34968
.cz83 websites
.com61 websites
.de24 websites
.net19 websites
.eu14 websites
.fr8 websites
.se6 websites
.be5 websites
.ch5 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-34968

Top websites that are affected by CVE-2026-34968. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.********.com Czech Republic**,***
*******.*****.cz Czech Republic***,***
******.*************.cz Czech Republic***,***
*******.***.cn China***,***
***.*******.net Poland*,***,***
***.*************.de Germany*,***,***
****.********.net United States*,***,***
********.cz Germany*,***,***
***.**************.de Germany*,***,***
*****************.*******************.de Germany*,***,***
See full domain list

FAQ

A total of 271 websites have been identified as vulnerable to CVE-2026-34968, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2026-34968 vulnerability.
Adminer versions up to 5.4.3 are vulnerable to CVE-2026-34968.
CVE-2026-34968 is resolved in version 5.4.3 of Adminer.